Skip to content

Services / Harden

Application Security

Security testing and architectural review across the full application estate, wherever it runs.

What you receive

  • Web, mobile, desktop and API security testing
  • Threat modelling against your architecture
  • Secure design review before build, not after

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    You are adding multi-tenancy to a product

    Tenant isolation lives in application code — a scanner cannot tell whether the identifier in a request belongs to the caller. We model the authorisation boundary, then test it by asking for another tenant's objects, one endpoint at a time.

  • 02

    The design is agreed but not yet built

    The cheapest moment to move a trust boundary is while it is still a diagram. We review the intended architecture — session model, authorisation model, key handling — and record the decisions, so the build has something to be tested against later.

  • 03

    Your mobile app is going into the app stores

    A mobile binary runs on the attacker's own hardware, so anything compiled into it — endpoints, keys, feature flags — is readable. We test what the client stores, what it trusts from the server, and what the server accepts when the client is bypassed.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.

  2. 02

    Written proposal

    Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.

  3. 03

    Delivery

    Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.

  4. 04

    Readout and retest

    A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • We test the application, not the platform beneath it — cloud account configuration and identity paths sit under Cloud Security.

  • This is not a source-code engagement; line-by-line review of your repositories is Code Security Analysis.

  • We do not write remediation code — every finding names a fix, but the change is made and shipped by your own engineers.

Measured against

OWASP ASVS 5.0
OWASP ASVS 5.0 defines tiered verification levels; state the level and edition the test scope is written against.
OWASP MASVS 2.0
Separates mobile functional security requirements from reverse-engineering resilience, which is assessed as its own category.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Is this just a penetration test with a different name?

There is real overlap in the testing phase. The difference is that this engagement also examines the design and the authorisation model, so part of it happens before anything is running and produces decisions rather than findings.

Can you test an application we have no documentation for?

Yes, but the first part of the engagement then goes on reconstructing what the roles and objects are. Without a role matrix, authorisation testing is partly guesswork, and undocumented applications reliably yield thinner findings for the same money.

Will you find every vulnerability in the application?

No, and anyone who says otherwise is selling. Testing is time-boxed, so we record what was covered and what was not reached — an area with no findings is an area with no findings, which is not the same as an area that is safe.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.